GitLab CE/EE Missing Authorization Check Vulnerability in Compliance Frameworks

Vulnerability

A vulnerability exists in GitLab CE/EE versions 17.11 prior to 17.11.4 and 18.0 prior to 18.0.2. The issue stems from a missing authorization check, which may have allowed compliance frameworks to be incorrectly applied to projects outside of the intended group.

Impact

Exploitation of this vulnerability could lead to improper application of compliance frameworks, allowing projects to be subjected to compliance requirements that are not applicable to them.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
0.6
exploitability
5.2
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.